Courseiva
Security →hardMultiple Select

DVA-C02 Security Practice Question

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "logs:CreateLogGroup"
      ],
      "Resource": "*"
    }
  ]
}

A developer is troubleshooting an AccessDenied error when a Lambda function tries to write to CloudWatch Logs. The function's IAM role includes the following policy. Which TWO missing permissions are causing the error? (Choose TWO.)

⚠ Common exam trap

Many candidates assume only PutLogEvents is needed for writing logs, forgetting that the Lambda runtime must also create the log stream if it does not already exist, making CreateLogStream a required permission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

logs:CreateLogStream

A Lambda function must call logs:CreateLogStream before it can write log events to a specific log stream. Without this permission, the function cannot create a new log stream when one does not already exist, resulting in an AccessDenied error. Option E is correct because logs:PutLogEvents is the permission required to actually write log events to an existing log stream; without it, the function cannot send log data to CloudWatch Logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    logs:DescribeLogStreams

    Why it's wrong here

    The logs:DescribeLogStreams permission allows an entity to list and retrieve metadata about log streams within a specified log group, such as their creation time or ARN. While useful for discovery, monitoring, or management purposes, it is not directly required for the act of writing log events. An AccessDenied error during a log write operation indicates a failure to perform the write action itself, not a failure to enumerate existing streams.

  • ✗

    logs:CreateLogGroup

    Why it's wrong here

    The logs:CreateLogGroup permission is required to initially establish a new log group within CloudWatch Logs. However, if the log group already exists and the application is attempting to write to it, this specific permission is not needed for subsequent log writing operations. An AccessDenied error during log event ingestion typically indicates a missing permission related to creating streams or putting events within an established group, not the group's initial creation.

  • ✓

    logs:CreateLogStream

    Why this is correct

    The logs:CreateLogStream permission is absolutely essential for an application to establish a new log stream within an existing CloudWatch Log Group. If the application attempts to write log events to a stream that does not yet exist, and it lacks this specific permission, it will inevitably encounter an AccessDenied error. This permission enables the necessary infrastructure for subsequent PutLogEvents calls to succeed.

  • ✗

    logs:GetLogEvents

    Why it's wrong here

    The logs:GetLogEvents permission is exclusively used for retrieving log events from a specific log stream, allowing users or applications to read historical data. It is a purely read-only operation and has no bearing on an application's ability to publish new log data. Therefore, an AccessDenied error encountered when an application is attempting to write new log events would not be resolved by adding this permission.

  • ✓

    logs:PutLogEvents

    Why this is correct

    The logs:PutLogEvents permission is fundamental for an application to publish actual log data into a CloudWatch Log Stream. Once a log group and log stream have been successfully created, this permission allows the application to send individual log events, including their timestamp and message, to be stored within that stream. Without logs:PutLogEvents, the application cannot successfully transmit any log data, leading to an AccessDenied error.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.